Overview
Seatly Software Ltd (“Seatly”) engages the following sub-processors to provide its restaurant booking SaaS platform. Each sub-processor has been assessed for compliance with UK GDPR and the UK Data Protection Act 2018. This document forms part of Seatly’s Data Processing Agreement (DPA) and is incorporated by reference into Seatly’s Privacy Policy.
Restaurant clients (data controllers) are notified of any changes to this list at least 30 days in advance via email to their registered account address. Clients may object to a new or changed sub-processor within that 30-day window by contacting privacy@seatly.uk. Where an objection cannot be resolved, either party may terminate the relevant service on written notice.
Sub-Processor Table
| Sub-Processor | Registered Address | Purpose | Personal Data Processed | Data Location | Transfer Mechanism | Sub-Processor DPA |
|---|---|---|---|---|---|---|
| Supabase Inc. | 970 Toa Payoh North, #07-04, Singapore 318992 | Database hosting, authentication, Edge Functions (serverless compute) | All booking and customer data: diner name, email address, phone number, booking details; restaurant staff credentials | London, UK (AWS eu-west-2) | Primary hosting in UK. Seatly does not intentionally store core booking data outside the UK. Any onward or remote access by the provider is governed by their contractual safeguards where applicable. | Supabase DPA |
| Resend Inc. | 2261 Market Street #5284, San Francisco, CA 94114, USA | Transactional email delivery (booking confirmations, reminders, cancellation notices) | Diner name, email address, booking reference | United States | UK IDTA / Standard Contractual Clauses (SCCs) | Resend DPA |
| Stripe Inc. | 510 Townsend Street, San Francisco, CA 94103, USA | Payment processing for restaurant subscription billing; diner deposit and pre-payment collection (group bookings, private dining, prime-time slots, and ticketed events) via Stripe Checkout, settled to the restaurant’s own connected Stripe account (Stripe Connect) | Restaurant billing contact name, email address, payment card data (tokenised), subscription details. Where a restaurant enables deposits or pre-payments: diner name, email address, and payment card details — entered on Stripe’s own hosted checkout page and held by Stripe. Seatly never stores diner card details. | United States / European Union | UK IDTA / Standard Contractual Clauses (SCCs) | Stripe Privacy & DPA |
| Cloudflare Inc. | 101 Townsend Street, San Francisco, CA 94107, USA | CDN, DNS, Pages hosting (widget and marketing site delivery), Turnstile anti-spam service; Workers AI — generates the plain-English summary sentence in the weekly insights email from anonymous aggregate booking statistics only (no personal data) | IP addresses, Turnstile challenge tokens (ephemeral, not linked to individuals). Workers AI processes aggregate counts only (total bookings, covers, cancellation rate, average party size, covers-by-day) — no names, email addresses, or phone numbers are passed to Workers AI. | Global edge network (EU inference preferred for Workers AI) | UK IDTA / Standard Contractual Clauses (SCCs) | Cloudflare DPA |
| Celerity Messaging UK Ltd (trading as BulkSMS.com) | 1st Floor Sackville House, 143–149 Fenchurch Street, London, EC3M 6BN, United Kingdom | Text (SMS) delivery — booking reminder texts and walk-in “table ready” notifications, delivery receipts, and inbound opt-out events | Diner phone number, text message content (diner first name, restaurant name, booking or queue details), delivery status | Republic of Ireland (AWS); limited group support access from Cape Town, South Africa | Hosting in Ireland (EEA) is covered by the UK’s adequacy regulations; the provider’s DPA incorporating Standard Contractual Clauses (SCCs) covers any South Africa support access | BulkSMS DPA |
Transfer Mechanisms — Definitions
- UK primary hosting — data is stored in the United Kingdom. Seatly does not intentionally store core booking data outside the UK for this service. Any onward or remote access by the provider is governed by their contractual safeguards where applicable.
- UK IDTA — UK International Data Transfer Agreement, issued under section 119A of the Data Protection Act 2018, used for transfers to third countries without an adequacy decision.
- Standard Contractual Clauses (SCCs) — European Commission standard data protection clauses adopted under Article 46(2)(c) UK GDPR, incorporated into the UK IDTA addendum where applicable.
Change Log
| Version | Date | Changed By | Summary of Changes |
|---|---|---|---|
| 1.0 | 2026-04-15 | Seatly Software Ltd | Initial publication |
| 1.1 | 2026-06-19 | Seatly Software Ltd | Added Workers AI as an additional purpose for Cloudflare Inc. (weekly insights email digest — aggregate data only, no personal data) |
| 1.2 | 2026-08-04 | Seatly Software Ltd | Corrected the Stripe entry: since deposit and pre-payment collection launched, Stripe also processes diner payment data (name, email, card details entered on Stripe’s hosted checkout) for payments settled to the restaurant’s connected account — the previous “no diner personal data” statement no longer held. Added Celerity Messaging UK Ltd (BulkSMS.com) as the text-message delivery sub-processor. |